Skip to content

What if the YubiKey is lost, how do you back up without getting locked out?

A hardware key is not a password, you cannot reset it. The only backup strategy that works is a second key. Not an SMS code, not a question, a second key in a safe.

Try this first

  1. 1Give every user with a hardware key at least two keys. A primary (key chain) and a backup (drawer at home or safe at the office). Register both in all systems at once, not after the first goes missing.
  2. 2For admins consider three keys: daily use, office safe, off-site at a colleague or in a safe-deposit box. Losing two at once becomes a genuinely rare event.
  3. 3Track which serial belongs to which user. On loss you block specifically in Entra (Authentication methods, FIDO2 security key, manage AAGUID and serial) so a finder cannot use it.
  4. 4For the Microsoft stack: keep at least two break-glass accounts, each with its own FIDO2 key in a physical safe. These accounts should not be in daily use and not in CA policies that can accidentally Block them.
  5. 5Once a quarter, test that a user can sign in with only the backup key, on Windows and on cloud portals. A key that is not tested fails on the worst possible day.

When to bring us in

Lose both keys without a backup account and you are looking at a Microsoft support case of days or weeks before admin access is restored. Costly, slow, and not how you want to learn this path the first time.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.